Mmcp.market

brazil-lgpd skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Guides compliance with Brazil''s Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018). Covers the 10 lawful bases under Art. 7, DPO appointment, ANPD enforcement, data subject rights under Arts. 17-22, and international transfer mechanisms. Keywords: LGPD, Brazil data protection, ANPD, lawful bases, data subject rights, international transfers.

A100/100content scan

Is the brazil-lgpd skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the brazil-lgpd skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/br/data-protection/skills/brazil-lgpd ~/.claude/skills/brazil-lgpd
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Brazil LGPD Compliance (Lei 13.709/2018)

Overview

The Lei Geral de Proteção de Dados Pessoais (LGPD), enacted as Lei 13.709 on 14 August 2018 and effective from 18 September 2020 (with sanctions enforceable from 1 August 2021), is Brazil's comprehensive data protection law. The LGPD applies to any processing of personal data carried out in Brazil, where the processing activity aims to offer goods or services to individuals located in Brazil, or where the personal data was collected in Brazil (Art. 3). The Autoridade Nacional de Proteção de Dados (ANPD) serves as the supervisory authority with rulemaking, enforcement, and advisory functions.

Ten Lawful Bases Under Article 7

The LGPD provides ten distinct legal bases for processing personal data, exceeding the six lawful bases under EU GDPR. Each base operates independently — organisations may rely on any applicable base without a prescribed hierarchy.

1. Consent of the Data Subject (Art. 7, I)

Requirements under Art. 8:

  • Consent must be provided in writing or by other means that demonstrate the free, informed, and unequivocal expression of the data subject's will
  • Written consent must appear in a clause separate from other contractual provisions (Art. 8, §1)
  • The burden of proof that consent was obtained rests with the controller (Art. 8, §2)
  • Consent is void if based on misleading information or where the data subject was not adequately informed (Art. 9, §1)
  • Consent may be revoked at any time by express statement of the data subject, via a free and facilitated procedure (Art. 8, §5)

Implementation at Zenith Global Enterprises:

  • Marketing communications to Brazilian customers require opt-in consent with a standalone consent clause
  • Consent records stored in the consent management platform with timestamp, scope, and version
  • Consent withdrawal mechanism accessible through the customer privacy portal within two clicks
  • Granular consent for each processing purpose (marketing, profiling, third-party sharing)

2. Compliance with Legal or Regulatory Obligation (Art. 7, II)

Scope: Processing necessary for the controller to comply with a legal or regulatory obligation under Brazilian law. This includes tax reporting under the Código Tributário Nacional, anti-money laundering under Lei 9.613/1998, and employment record retention under the Consolidação das Leis do Trabalho (CLT).

Implementation at Zenith Global Enterprises:

  • Employee payroll records retained for 5 years per CTN Art. 173
  • Employment records retained for the duration of the employment relationship plus 5 years per CLT Art. 11
  • Anti-money laundering records retained for 5 years from the last transaction per Lei 9.613/1998, Art. 10

3. Execution of Public Policies by the Public Administration (Art. 7, III)

Scope: Processing by the public administration for the execution of public policies provided in laws, regulations, or contracts. This base is available only to public administration bodies and is not applicable to private-sector organisations.

Zenith Global Enterprises relevance: Not applicable as a private-sector entity. If engaged in public-private partnerships, the government partner invokes this base.

4. Research by Research Bodies (Art. 7, IV)

Scope: Processing for carrying out studies by research bodies, ensuring anonymisation of personal data whenever possible. Research bodies must comply with specific ethical standards and are subject to oversight by the relevant ethics committees.

Zenith Global Enterprises relevance: If collaborating with academic institutions on logistics optimisation research, ensure data shared for research purposes is anonymised or pseudonymised with the research body assuming controller responsibility.

5. Contract Performance (Art. 7, V)

Scope: Processing necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party, at the request of the data subject.

Implementation at Zenith Global Enterprises:

  • Processing customer shipping addresses, contact details, and payment information to fulfil freight forwarding contracts
  • Pre-contractual processing of credit assessments when customers request trade credit terms
  • Processing employee data necessary for execution of the employment contract

6. Exercise of Rights in Judicial, Administrative, or Arbitration Proceedings (Art. 7, VI)

Scope: Processing necessary for the regular exercise of rights in judicial, administrative, or arbitration proceedings. This permits retention and use of personal data where necessary for litigation or regulatory proceedings.

Implementation at Zenith Global Enterprises:

  • Retention of customer correspondence and transaction records relevant to pending or anticipated customs disputes
  • Preservation of employee performance records where termination is contested before the Justiça do Trabalho (Labour Courts)

7. Protection of Life or Physical Safety (Art. 7, VII)

Scope: Processing necessary for the protection of the life or physical safety of the data subject or a third party. This base is reserved for genuine emergency situations where consent cannot reasonably be obtained.

Implementation at Zenith Global Enterprises:

  • Processing of employee medical emergency information during workplace incidents at Brazilian warehouse facilities
  • Sharing driver location data with emergency services during road transport incidents

8. Health Protection (Art. 7, VIII)

Scope: Processing necessary for the protection of health, exclusively in a procedure carried out by health professionals, health services, or health authorities. This base is narrower than the life protection base and is restricted to health-sector actors.

Zenith Global Enterprises relevance: Limited to occupational health processing by the company's contracted occupational medicine providers under Norma Regulamentadora NR-7 (PCMSO).

9. Legitimate Interest of the Controller or Third Party (Art. 7, IX)

Requirements under Art. 10:

  • Processing must be for legitimate purposes based on concrete situations, including:
  • (I) Support and promotion of the controller's activities
  • (II) Protection of the data subject or of the provision of services that benefit the data subject, in connection with the exercise of their rights
  • Only strictly necessary data may be processed for the stated purpose
  • The controller must adopt transparency measures, including a legitimate interest impact assessment
  • If the ANPD requests it, the controller must produce a Relatório de Impacto à Proteção de Dados Pessoais (RIPD) — the LGPD equivalent of a DPIA

Implementation at Zenith Global Enterprises:

  • Fraud detection on customer payment transactions using pattern analysis
  • IT security monitoring of employee network activity to prevent data breaches
  • Customer relationship management analytics to improve service quality
  • Legitimate interest assessment documented for each use case using the three-part balancing test: (1) legitimate purpose, (2) necessity, (3) balancing against data subject rights

10. Credit Protection (Art. 7, X)

Scope: Processing for the protection of credit, including credit scoring. This base is unique to the LGPD and has no direct equivalent in the GDPR. It permits processing for credit risk assessment, credit bureau operations, and commercial credit evaluation.

Implementation at Zenith Global Enterprises:

  • Credit scoring of corporate customers applying for trade credit terms
  • Sharing payment history with credit bureaus (Serasa Experian, SPC Brasil, Boa Vista) in compliance with Lei 12.414/2011 (Positive Credit Registry)
  • Retention of credit assessment records for the statutory period

Sensitive Data Processing Under Article 11

Sensitive personal data (dados pessoais sensíveis) includes data on racial or ethnic origin, religious conviction, political opinion, trade union membership, health data, sex life, genetic data, and biometric data (Art. 5, II).

Processing of sensitive data requires one of eight specific bases under Art. 11:

  1. Specific and highlighted consent from the data subject
  2. Compliance with a legal obligation (without consent)
  3. Shared processing by the public administration for public policy execution
  4. Research bodies (with anonymisation where possible)
  5. Exercise of rights in judicial/administrative/arbitration proceedings
  6. Protection of life or physical safety
  7. Health protection in medical procedures
  8. Fraud prevention and security of the data subject in identification processes

Key distinction from GDPR: The LGPD does not include legitimate interest or contract performance as bases for sensitive data processing.

Data Protection Officer (Encarregado) Requirements

Appointment (Art. 41)

The controller must appoint a Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais). ANPD Resolution CD/ANPD No. 2/2022 (amended by Resolution CD/ANPD No. 18/2024) provides that:

  • Small-scale processing agents (agentes de tratamento de pequeno porte) may appoint a simplified contact channel instead of a formal DPO
  • The DPO's identity and contact information must be publicly disclosed, preferably on the controller's website
  • The ANPD may establish additional rules regarding the DPO's qualifications

DPO Functions (Art. 41, §2)

Zenith Global Enterprises DPO Structure

Data Subject Rights (Arts. 17-22)

Rights Catalogue

Right to Review Automated Decisions (Art. 20)

The data subject has the right to request review of decisions made solely on the basis of automated processing, including profiling, that affect their interests. The controller must provide clear and adequate information regarding the criteria and procedures used for automated decision-making, subject to commercial and industrial secrecy.

ANPD Resolution CD/ANPD No. 2/2022 clarified that small-scale processing agents may provide simplified explanations, but all controllers must enable human review upon request.

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers